Privacy
Effective date: 27 April 2026 · Last updated: 22 May 2026
What we collect, where it lives, and what we do with it. Operated by M1 Factory, Inc.
Your knowledge lives in our database under your account. We don’t read it for product purposes, we don’t train AI on it, and we don’t share it outside the subprocessors listed below. When you connect an AI assistant via MCP, it reads only what you’ve granted it access to — your credentials are never shared with the AI provider. We have operator-level access to the infrastructure we run.
Do not store Social Security numbers, government-issued ID numbers, passwords, financial account credentials, medical records, or any data governed by HIPAA, GLBA, FERPA, or equivalent laws. KnoMe is not certified or designed for regulated data.
1. Scope and definitions
Account data — your email address, optional display name, and authentication records.
Customer data — everything you add to KnoMe: rooms, categories, entries, notes, links, and files. Also includes anything an AI assistant writes on your behalf via MCP.
Personal data — information about identifiable individuals processed in connection with providing the service. M1 Factory, Inc. acts as the data controller for personal data it collects directly (account data, analytics). Where you store third-party personal data inside KnoMe, you are the controller of that data.
2. Data we collect
us.i.posthog.com in your browser.3. How we use data
- To provide and operate the KnoMe service
- To authenticate you and keep your session secure
- To understand how features are used and diagnose issues (aggregate and session-level)
- To detect and prevent abuse and rate-limit excessive API usage
- To contact you about significant service changes (email only)
- To meet legal obligations (tax records, court orders)
We do not sell, rent, or syndicate your data. We do not use your content to train or fine-tune any AI model.
4. Legal basis for processing (GDPR)
For users in the European Economic Area or United Kingdom, we process personal data under the following legal bases:
Where we rely on legitimate interests, you have the right to object (see Section 10). We have assessed that our interests do not override your fundamental rights and freedoms.
5. AI assistant access (MCP)
When you connect an AI assistant (such as Claude) to KnoMe via our MCP server, the assistant reads and writes data on your behalf using only the permissions you have granted via OAuth 2.0. Your KnoMe credentials are never shared with or seen by the AI provider.
Data returned to the AI assistant travels to that provider under their published data-handling policy. We don’t control what happens to data once it leaves our servers and enters a prompt.
6. Where data lives
All primary processing occurs in the United States.
7. Subprocessors
No other third parties receive your data.
8. Data retention and deletion
Account deletion is a one-way door. When you request deletion, your account, rooms, entries, and files are removed. Email meet@m1factory.com to delete your account.
9. Security (excerpt)
- Encrypted at rest. All customer data is stored in Supabase (PostgreSQL) and encrypted at rest by the platform. OAuth tokens are SHA-256 hashed before storage — the raw token is never persisted.
- Encrypted in transit. TLS 1.2+ is enforced on all public endpoints. HTTP connections are rejected at the edge.
- Not end-to-end encrypted. KnoMe reads your content in cleartext so that AI assistants can retrieve it. This is intrinsic to how the product works — encryption at rest protects your data at the storage layer, but does not prevent server-side access.
- No third-party certifications. We do not hold SOC 2, ISO 27001, or comparable certifications. See the Security page for what is in place today.
10. Your rights
Depending on your location, you may have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — ask us to correct inaccurate information
- Deletion — ask us to delete your account and all associated personal data
- Portability — receive your data in a machine-readable format
- Restrict processing — ask us to limit how we use your data while a dispute is resolved
- Object — object to processing based on legitimate interests, including session replay analytics
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing
To exercise any of these rights email meet@m1factory.com. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority (e.g. the ICO in the UK, or your EU Member State’s data protection authority).
11. International data transfers
The service is operated from the United States. If you are located in the European Economic Area, United Kingdom, or Switzerland, your personal data is transferred to and processed in the US. We rely on Standard Contractual Clauses (SCCs) as the transfer mechanism for EEA/UK data. A copy of the applicable SCCs is available on request at meet@m1factory.com.
12. Breach notification
We will notify affected users by email within 72 hours of confirming a data incident, with details and updates as the investigation proceeds. Where required by law, we will also notify the relevant supervisory authority.
13. Children
KnoMe is not directed at individuals under 16. We do not knowingly collect personal information from anyone under 16. Contact us immediately at meet@m1factory.com if you believe we have done so.
14. Changes to this page
Material changes will be communicated by email at least 14 days before they take effect. The date at the top of this page reflects the most recent version.
15. Contact and DPO
Privacy questions: meet@m1factory.com
No Data Protection Officer has been designated at this time. This page will be updated if one is appointed. For data protection enquiries, contact us at the email above.